Back to news
Cybersecurity Alert
June 5, 2026 by EmailMeNow IT Consulting

Cybersecurity Audit of Top Pennsylvania Accounting Firms in 2026

Independent audits of major Pennsylvania accounting firms reveal a wide range of cybersecurity results. The IRS (Publication 4557) requires every tax professional to maintain a written information security plan (WISP) to keep a PTIN, and the FTC Safeguards Rule backs it with civil penalties.

CPAAccountingTaxIRS Pub 4557Email SecurityPennsylvania
Digital audit dashboard with a Pennsylvania state map showing cybersecurity scores of major Pennsylvania accounting firms

An independent cybersecurity review across many of Pennsylvania’s largest accounting firms reveals a wide range of results. Firms that prepare returns hold extremely sensitive taxpayer data, yet many show significant gaps in basic email authentication.

Using data from audit.emailmenow.com, we evaluated each firm’s domain across SPF, DKIM, DMARC, transport security (MTA-STS/TLS), and website security headers.

Cybersecurity Scores of Major Pennsylvania Accounting Firms

Overall compliance scores from audit.emailmenow.com. Re-run any domain at the link to verify.

RankFirmDomainOverall ScorePerformance Level
1Maillie LLPmaillie.com70%Strong
2Schneider Downsschneiderdowns.com66%Good
3Herbein + Companyherbein.com64%Good
3Kreischer Millerkmco.com64%Good
3Sisterson & Co.sisterson.com64%Good
6Trout CPAtroutcpa.com60%Above Average
7McKonly & Asburymacpas.com58%Average
8Brown Plusbrownplus.com54%Average
8Boyer & Ritterboyercpa.com54%Average
10RKLrklcpa.com51%Below Average
11Isdaner & Companyisdanerllc.com44%Weak

What the Results Reveal

  • Scores range from 70% (Maillie) down to 44% — Maillie is the only Pennsylvania firm to reach a strong posture, with a cluster of well-known firms at 64%.
  • The middle and lower pack show enforced DMARC (p=reject), strict SPF, and transport protections are widely incomplete, despite the taxpayer data these firms hold.
  • Weak email authentication fuels the tax-season phishing and client-payment fraud that increasingly target CPA firms.

Why This Matters for Accounting Firms

The IRS (Publication 4557) requires every tax professional to maintain a written information security plan (WISP) to keep a PTIN, and the FTC Safeguards Rule backs it with civil penalties. Tax season is also peak phishing season for tax pros.

Check any firm’s posture at audit.emailmenow.com/?industry=cpa-firms.

See also — national audit

Recommendations

  • Enforce DMARC (p=reject), strict SPF (-all), and DKIM signing.
  • Add MTA-STS and website security headers.
  • Document your WISP and run recurring security awareness training before filing season.

Protect your firm and your clients. Run a free Instant Cybersecurity Audit at audit.emailmenow.com/?industry=cpa-firms.

Contact EmailMeNow IT Consulting for help with your IRS-ready written security plan and email hardening.


Source & methodology: Overall compliance scores from the free scan at audit.emailmenow.com — each domain checked for email authentication (SPF, DKIM, DMARC), transport security (MTA-STS/TLS), website security headers, and network security. Re-run any domain at the link to verify.